PT-2022-25630 · Unknown · Zoo Management System

Lime

·

Published

2022-09-22

·

Updated

2023-11-14

·

CVE-2022-40932

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoo Management System version 1.0
Description The issue is related to an arbitrary file upload vulnerability. This vulnerability is located in the picture upload point of the gallery file of the Gallery module in the background management system.
Recommendations For Zoo Management System version 1.0, consider restricting access to the gallery file in the Gallery module to minimize the risk of exploitation. As a temporary workaround, avoid using the picture upload feature in the background management system until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-40932

Affected Products

Zoo Management System